postgres configured

This commit is contained in:
bogale 2026-09-26 16:42:02 +09:00
commit d2b59d97cb
5 changed files with 57 additions and 30 deletions

View file

@ -51,6 +51,18 @@
jq
sbctl
];
programs = {
git = {
enable = true;
config = {
init.defaultbranch = "main";
user = {
name = "bogale";
email = "git@bogaledev.ru";
};
};
};
};
services = {
logind.settings.Login.HandleLidSwitch = "ignore";
nginx = {

View file

@ -12,16 +12,6 @@
historyControl = [ "ignoreboth" ];
shellAliases = { la = "ls -lAtr"; };
};
git = {
enable = true;
settings = {
init.defaultbranch = "main";
user = {
name = "bogale";
email = "git@bogaledev.ru";
};
};
};
neovim = {
enable = true;
defaultEditor = true;

1
marks
View file

@ -12,5 +12,4 @@ nixos-install --flake "/mnt/etc/nixos#nixos" --no-channel-copy --no-root-passwd
systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 <LUKS_DEV>
todo:
- mediawiki
- email tracking

View file

@ -46,18 +46,22 @@
LogLevelMax = "notice";
};
script = ''
if [ ! -e /run/network.failures ] || \
${pkgs.iputils}/bin/ping -c 1 -W 3 1.1.1.1; then
if [ ! -e /run/network.failures ] || [ ! -e /run/network.limit ] || \
${pkgs.curl}/bin/curl --head --max-time 3 https://www.google.com; then
limit=3
failures=0
else
limit=$(cat /run/network.limit)
failures=$((1+$(cat /run/network.failures)))
echo "<5>failures = $failures"
fi
if [ $failures -ge 3 ]; then
if [ $failures -ge $limit ]; then
echo "<4>restarting NetworkManager"
systemctl restart NetworkManager.service
[ $limit -lt 60 ] && limit=$((4*$limit/3))
failures=0
fi
echo $limit > /run/network.limit
echo $failures > /run/network.failures
'';
};

View file

@ -14,16 +14,18 @@
services = let
sslCertDir = config.security.acme.certs."bogaledev.ru".directory;
in {
postgresql.enable = true;
phpfpm.pools.default = {
user = "php";
group = "php";
settings = {
"pm" = "ondemand";
"pm.max_children" = 8;
"listen.owner" = "nginx";
"listen.group" = "nginx";
postgresqlBackup = {
enable = true;
compression = "none";
databases = [ "php" "forgejo" "vaultwarden" ];
};
postgresql = {
enable = true;
ensureDatabases = [ "php" ];
ensureUsers = [ {
name = "php";
ensureDBOwnership = true;
} ];
};
forgejo = {
enable = true;
@ -36,6 +38,17 @@
};
};
};
phpfpm.pools.php = {
user = "php";
group = "php";
phpEnv = { PATH = "/run/current-system/sw/bin"; };
settings = {
"pm" = "ondemand";
"pm.max_children" = 8;
"listen.owner" = "nginx";
"listen.group" = "nginx";
};
};
vaultwarden = {
enable = true;
dbBackend = "postgresql";
@ -52,9 +65,9 @@
};
};
nginx.virtualHosts."bogaledev.ru" = let
phpPool = pool: ''
phpPool = ''
location ~ \.php$ {
fastcgi_pass unix:${config.services.phpfpm.pools.${pool}.socket};
fastcgi_pass unix:${config.services.phpfpm.pools.php.socket};
}
'';
localNetworks = ''
@ -70,16 +83,25 @@
forceSSL = true;
root = "/srv/http";
useACMEHost = "bogaledev.ru";
extraConfig = ''add_header Alt-Svc 'h3=":443"; ma=86400' always;'';
extraConfig = ''
add_header Alt-Svc 'h3=":443"; ma=2592000' always;
add_header X-Content-Type-Options "nosniff" always;
'';
locations = {
"/app/".extraConfig = phpPool "default";
"/git/".proxyPass = "http://127.0.0.1:8039/";
"/local/".extraConfig = ''${phpPool "default"} ${localNetworks}'';
"/" = {
extraConfig = phpPool;
index = "index.php index.html";
};
"/local/" = {
extraConfig = "${phpPool} ${localNetworks}";
index = "index.php index.html";
};
"/local/net/".extraConfig = ''
allow fc01::/64;
allow 10.1.0.0/16;
deny all;
'';
"/git/".proxyPass = "http://127.0.0.1:8039/";
"/vw/" = {
proxyWebsockets = true;
extraConfig = localNetworks;